Opening a financial account is much more than just creating a username, linking a wallet or assigning an account number. Financial service providers need to know who their customers are, understand their risk profiles and have appropriate controls in place throughout the customer relationship. That is where account layer compliance plays an important role in modern financial infrastructure.
Collaborative content
These controls are based on KYC or Know Your Customer. Effective KYC can also help establish a compliant relationship in the case of platforms that connect users to payments, fiat accounts, stablecoins, cards or other financial services before transactions even begin. Customer due diligence is a process that includes identifying, verifying and ongoing monitoring of customers, according to the Financial Action Task Force.
What Is Account Layer Compliance?
An account layer is an abstraction between a financial product and the underlying infrastructure needed to make that product work. This could include identity, account creation, payment rails, compliance controls, transaction records and other financial services, depending on the provider and jurisdiction.
Account layer compliance is the regulatory controls baked into that infrastructure.
Instead of treating compliance as a process that happens only after an account is created, organizations can embed controls into account creation and ongoing account management. This approach can tie identity verification to the services users access after approval.
The specific regulatory requirements will vary based on the business model, licensing structure, jurisdiction and financial activities being undertaken. But the basic premise is the same: a business needs to have a reliable means of knowing who its customers are and managing the risks of providing financial services to them.
Why KYC Should Be At Account Level
KYC is often linked with onboarding, but it extends beyond the first verification step.
A financial account is an ongoing relationship between a provider and a customer. It can include things like deposits, transfers, card payments, conversions, withdrawals and so on. If identity information only exists in a disconnected onboarding system, compliance teams might find it difficult to connect customer information to account activity.
An account-level approach can help build a stronger relationship between:
- Identity: Who has ownership or control of the account?
- Verification: Is the customer’s information properly verified?
- Risk: Does the customer’s activity warrant further review?
- Transactions: Where is the money going to?
- Monitoring: Are changes in customer or transaction activity detected?
The FATF guidance notes that the processes of identification, verification and monitoring are all components of customer due diligence.
That makes KYC more than just an upload of documents. It is embedded into the operational infrastructure of the account.
Difference Between KYC and AML
KYC and AML are related, but they are not the same thing.
KYC is mainly about customer identity establishment and verification. This may include, depending on the applicable requirements, collecting identifying information, verifying documents, assessing customer information and understanding beneficial ownership.
AML or anti-money laundering is a broader set of controls that are designed to detect and mitigate money laundering and other financial crime risks.
For example, FinCEN’s customer due diligence regime for covered financial institutions includes procedures to identify and verify customers and, where appropriate, the beneficial owners of legal entity customers.
Therefore, a business should not assume that successful KYC automatically means its AML responsibilities are complete. Identity verification provides important information, but may also be accompanied by ongoing monitoring, risk assessment, recordkeeping and other controls.
What Account Layer Compliance That Works May Be
The exact control framework differs between providers and jurisdictions. But a well-designed account infrastructure can make several compliance functions more similar.
Identity authentication
The first step is to verify that the person or organization opening an account is who they claim to be.
There are different ways to verify. These can be government issued IDs, biometric checks, business information or other approved verification methods. The right approach will depend on the risk and regulatory requirements of the service.
Beneficial Ownership Verification
Things get a little more complicated with business accounts. If a company has directors, shareholders, controllers or other beneficial owners that are required to be identified under applicable rules.
Linking this information to the account provides compliance teams with a more holistic view of the entity behind the financial activity.
Monitoring based on risk
KYC doesn’t have to stop at account approval.
Customer situation and transaction behavior may change. A risk-based monitoring framework can assist in identifying activity that may require further investigation or review. The FATF guidance explicitly links customer due diligence with ongoing monitoring of the customer and the customer’s transactions.
Auditing and Record Keeping
Compliance teams need reliable records to demonstrate how decisions were made around identity and risk.
If the infrastructure provider links account activity, identity information, and transaction records, it can enable the creation of an auditable history. The precise recordkeeping obligations are still subject to the applicable regulatory regime.
The Importance of Compliance Architecture for Fintechs
It can take longer to build financial services in-house than software development. A business may require banking relationships, payment integrations, compliance staff, identity verification systems, monitoring and reporting tools, as well as suitable licensing or regulated partners.
This is particularly important for wallets, exchanges, fintech applications and platforms that want to offer both digital currencies and conventional financial services.
Modular account infrastructure cuts down on the effort to assemble each component separately. Instead, companies can embed some capabilities while keeping the customer experience they want.
For example, UR describes its infrastructure as a hybrid of stablecoin and fiat rails, with accounts, payments, cards, and built-in KYC and AML controls. According to its platform materials, KYC and compliance are managed through its regulated infrastructure, enabling partners to add financial functionality without having to build the entire compliance stack themselves.
That model doesn’t remove the need for businesses to know their own regulatory responsibilities. Rather, it moves where some infrastructure and compliance functions occur.
Common KYC Challenges That Companies Face
When compliance systems are not connected to the customer experience, putting KYC into practice can cause friction.
Several issues deserve special attention:
Bad Data Quality
Wrong names, old documents, partial business information or inconsistent records may cause unnecessary verification issues.
Broken Compliance Regimes
Keeping identity, accounts, transactions and monitoring in separate systems makes it harder to maintain a single, consistent customer record.
Onboarding Hassle Too Much
Strong compliance controls don’t have to mean an overly complicated onboarding process. Businesses have to balance regulatory requirements with a practical user experience.
Lack of Regular Monitoring
The customer who passed KYC at the time of opening an account may not be the same risk months or years later. Monitoring must therefore reflect the continuous nature of the financial relationship.
How to Build a Stronger KYC Framework for Business
A practical approach is to start by mapping the customer journey from account creation to continued use.
First, determine which regulatory obligations apply to the business and its target markets. Second, decide what customer information you need to collect and how you will verify it.
The business should then connect identity records to account activity and establish procedures for risk assessment, monitoring, escalation and record retention.
Finally, compliance controls should be reviewed on a regular basis. Regulatory requirements can change, business models evolve and new financial products can introduce different risks.
Bottom Line
KYC works best when it is seen as part of the infrastructure of a financial account rather than as a one-time onboarding task. The compliance in the account layer links the identity verification to the access to the account, the transaction activity and the monitoring and auditability, hence providing a more coherent basis for regulated financial services.
For businesses building stablecoin-enabled wallets, fintech platforms, payment products or services, the key question is not whether KYC exists. It is how effectively identity and compliance controls integrate with the account throughout its lifecycle.
A well-designed compliance architecture can give businesses a clearer way to manage customer relationships, while supporting the financial services built on top of the account layer.
Disclaimer: the author(s) of the sponsored article(s) are solely responsible for any opinions expressed or offers made. These opinions do not necessarily reflect the official position of Daily News Hungary, and the editorial staff cannot be held responsible for their veracity.